-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Affects Version/s: 2.2.1, 2.2.5, 2.2.9
-
Component/s: Search - Core
Comments attached to pages that inherit restrictions from parent pages seem to ignore the inherited permissions in the Confluence index.
Steps to reproduce:
1) Enable anonymous Confluence access
2) Create a space with anonymous access
3) Add a page and restrict view to confluence-users
4) Add a subpage
5) Add a comment to this subpage
The comment will appear in the dashboard recently updated list even for anonymous users. Trying to access it however will result in a credentials check.
The comment will also appear in any public RSS feed which only has "comment" in its type list. Curiously they won't appear if the feed is configured to filter other content types such as pages.
Adding a comment directly to the parent page which has the restriction set does not trigger this behaviour.
- is duplicated by
-
CONFSERVER-7911 Comment appears on recently updated even though it was page permission restricted
-
- Closed
-
-
CONFSERVER-9002 Security: Comments visible on dashboard: recent changes while page view is closed for users
-
- Closed
-